starrkiller
Posts: 60 +0
Hello!
I found the computer having a strange behaviour, the cpu is working hard even when I am not running any software that causes it. Also, sometimes ccleaner or mawarebites wont open if I dont boot in safe mode.
Here are my logs:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-04-2015
Ran by Dave (administrator) on LEGIAO on 14-04-2015 19:29:40
Running from C:\Users\Dave\Downloads
Loaded Profiles: Dave (Available profiles: Dave)
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
() C:\Program Files\Autodesk\3ds Max 2014\NVIDIA\Satellite\raysat_3dsmax2014_64server.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe
() C:\ExpressGateUtil\VAWinService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Kaspersky Lab ZAO) C:\Users\Dave\AppData\Local\Temp\{B930B6AF-9844-47CA-B2B4-54D5CB95DCB2}.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Sentelic Corporation) C:\Program Files\FSP\FspUip.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
(BitTorrent Inc.) C:\Users\Dave\AppData\Roaming\uTorrent\uTorrent.exe
() C:\Users\Dave\AppData\Local\Viber\Viber.exe
(Dropbox, Inc.) C:\Users\Dave\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
() C:\ExpressGateUtil\VAWinAgent.exe
(Windows (R) Win 7 DDK provider) C:\Program Files\Fresco Logic\Fresco Logic USB3.0 Host Controller\amd64_host\FLxHCIm.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12446824 2012-01-31] (Realtek Semiconductor)
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [7477016 2013-04-25] (Logitech Inc.)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3091224 2013-08-01] (Logitech, Inc.)
HKLM\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [418280 2012-07-26] (Autodesk, Inc.)
HKLM\...\Run: [fspuip] => C:\Program Files\FSP\fspuip.exe [4285952 2011-06-19] (Sentelic Corporation)
HKLM\...\Run: [THXCfg64] => C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2461504 2014-09-17] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [VAWinAgent] => C:\ExpressGateUtil\VAWinAgent.exe [45448 2011-04-08] ()
HKLM-x32\...\Run: [FLxHCIm64] => C:\Program Files\Fresco Logic\Fresco Logic USB3.0 Host Controller\amd64_host\FLxHCIm.exe [48128 2012-07-19] (Windows (R) Win 7 DDK provider)
HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2321072 2012-02-02] (ASUSTeK Computer Inc.)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [318080 2011-12-22] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [174720 2011-10-24] (ASUS)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [THX TruStudio NB Settings] => C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe [909312 2011-03-16] (Creative Technology Ltd)
HKLM-x32\...\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2013\avgui.exe [4411952 2014-11-04] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3478392 2013-09-05] (Adobe Systems Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\RunOnce: [{7F899E6A-EA93-47DC-88DA-5EE53B87FDDB}] => cmd.exe /C start /D "C:\Users\Dave\AppData\Local\Temp" /B {7F899E6A-EA93-47DC-88DA-5EE53B87FDDB}.cmd
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-4239578433-150447082-3389053847-1000\...\Run: [uTorrent] => C:\Users\Dave\AppData\Roaming\uTorrent\uTorrent.exe [1377872 2015-01-30] (BitTorrent Inc.)
HKU\S-1-5-21-4239578433-150447082-3389053847-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673696 2013-08-01] (Disc Soft Ltd)
HKU\S-1-5-21-4239578433-150447082-3389053847-1000\...\Run: [Viber] => C:\Users\Dave\AppData\Local\Viber\Viber.exe [912904 2013-07-31] ()
HKU\S-1-5-21-4239578433-150447082-3389053847-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7416088 2015-02-19] (Piriform Ltd)
HKU\S-1-5-21-4239578433-150447082-3389053847-1000\...\Run: [MCShield Monitor] => C:\Program Files (x86)\MCShield\mcshieldrtm.exe [650816 2014-04-11] (MyCity)
HKU\S-1-5-21-4239578433-150447082-3389053847-1000\...\Policies\Explorer: []
Startup: C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Dave\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Registo do produto.lnk
ShortcutTarget: Logitech . Registo do produto.lnk -> C:\Program Files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe (Leader Technologies/Logitech)
Startup: C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Deskjet 1510 series.lnk
ShortcutTarget: Monitor Ink Alerts - HP Deskjet 1510 series.lnk -> C:\Program Files\HP\HP Deskjet 1510 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
Startup: C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Windows Explorer.lnk
ShortcutTarget: Windows Explorer.lnk -> C:\Users\Dave\AppData\Roaming\sduisg\diskmonitor.exe (Microsoft Corporation)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-4239578433-150447082-3389053847-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-4239578433-150447082-3389053847-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2013-10-17] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2013-09-05] (Adobe Systems Incorporated)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2013-08-01] (Logitech, Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2013-09-13] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2013-11-02] (Microsoft Corporation)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2013-09-05] (Adobe Systems Incorporated)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2013-10-17] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-09-18] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO-x32: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File
BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2013-09-05] (Adobe Systems Incorporated)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2013-08-01] (Logitech, Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2013-09-13] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2013-11-02] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-09-18] (Oracle Corporation)
BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2013-09-05] (Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2013-09-05] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2013-09-05] (Adobe Systems Incorporated)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\0rp4oki1.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-06] ()
FF Plugin: @garmin.com/GpsControl -> C:\Program Files\Garmin GPS Plugin\npGarmin.dll [2014-03-31] (GARMIN Corp.)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2012-09-20] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-06] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2013-09-09] ()
FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll [2014-03-31] (GARMIN Corp.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.40.2 -> C:\Windows\SysWOW64\npDeployJava1.dll [2013-09-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.40.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2013-09-18] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2013-10-17] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @nullsoft.com/winampDetector;version=1 -> C:\Program Files (x86)\Winamp Detect\npwachk.dll [2013-07-24] (Nullsoft, Inc.)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2014-11-13] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2014-11-13] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll [2013-09-26] (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2012-09-20] (Adobe Systems)
FF Plugin HKU\S-1-5-21-4239578433-150447082-3389053847-1000: @citrixonline.com/appdetectorplugin -> C:\Users\Dave\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2015-03-31] (Citrix Online)
FF Plugin HKU\S-1-5-21-4239578433-150447082-3389053847-1000: @talk.google.com/GoogleTalkPlugin -> C:\Users\Dave\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-03-26] (Google)
FF Plugin HKU\S-1-5-21-4239578433-150447082-3389053847-1000: @talk.google.com/O1DPlugin -> C:\Users\Dave\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-03-26] (Google)
FF Plugin HKU\S-1-5-21-4239578433-150447082-3389053847-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Dave\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-08] (Google Inc.)
FF Plugin HKU\S-1-5-21-4239578433-150447082-3389053847-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Dave\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-08] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2013-10-17] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Dave\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-03-26] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Dave\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-03-26] (Google)
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-10-30]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2013-08-12]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2013-11-20]
Chrome:
=======
CHR Profile: C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-10-12]
CHR Extension: (Google Docs) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-10-12]
CHR Extension: (Google Drive) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-10-12]
CHR Extension: (YouTube) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-10-12]
CHR Extension: (Google Search) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-10-12]
CHR Extension: (Adobe Acrobat - Create PDF) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2013-12-02]
CHR Extension: (Google Sheets) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-10-12]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-12]
CHR Extension: (Skype Click to Call) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-09-07]
CHR Extension: (Google Wallet) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-07]
CHR Extension: (Gmail) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-10-12]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2013-09-05]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
CHR HKLM-x32\...\Chrome\Extension: [oejkcgajlodefenbbjdnaiahmbnnoole] - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\chrome-newtab-search.crx [Not Found]
Opera:
=======
StartMenuInternet: (HKU\S-1-5-21-4239578433-150447082-3389053847-1000) OperaMail - "C:\Users\Dave\AppData\Local\Opera Mail\OperaMail.exe"
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [19232 2012-01-31] (Autodesk, Inc.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [4942384 2014-10-17] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [283136 2013-11-20] (AVG Technologies CZ, s.r.o.)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
S3 Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2013-08-15] (Creative Labs) [File not signed]
S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2013-08-15] (Creative Labs) [File not signed]
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2013-09-15] (Macrovision Europe Ltd.) [File not signed]
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1149760 2014-09-17] (NVIDIA Corporation)
R2 mi-raysat_3dsmax2014_64; C:\Program Files\Autodesk\3ds Max 2014\NVIDIA\Satellite\raysat_3dsmax2014_64server.exe [86016 2011-09-15] () [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1796928 2014-09-17] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19440960 2014-09-17] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-08-22] ()
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 VideAceWindowsService; C:\ExpressGateUtil\VAWinService.exe [91464 2011-03-25] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R0 4EEDD889; C:\Windows\System32\drivers\4EEDD889.sys [457824 2015-04-14] (Kaspersky Lab ZAO)
R3 AiCharger; C:\Windows\SysWOW64\DRIVERS\AiCharger.sys [17152 2012-01-30] (ASUSTek Computer Inc.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [246072 2013-11-25] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [71480 2013-07-20] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [209720 2014-11-04] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [311608 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [116536 2013-07-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [45880 2013-10-23] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [240952 2014-10-17] (AVG Technologies CZ, s.r.o.)
S3 cpuz135; C:\Program Files (x86)\CPUID\PC Wizard 2012\pcwiz_x64.sys [24368 2012-08-11] (CPUID)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-08-12] (Disc Soft Ltd)
R3 FLxHCIh; C:\Windows\System32\DRIVERS\FLxHCIh.sys [76584 2012-07-19] (Fresco Logic)
R3 fspad_win764; C:\Windows\System32\DRIVERS\fspad_win764.sys [53760 2011-06-19] (Windows (R) Win 7 DDK provider)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-08-15] (GFI Software)
S3 ggsomc; C:\Windows\System32\DRIVERS\ggsomc.sys [30424 2014-12-25] (Sony Mobile Communications)
R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [66800 2013-01-17] (Logitech Inc.)
R3 LGSUsbFilt; C:\Windows\System32\DRIVERS\LGSUsbFilt.Sys [44272 2013-01-17] (Logitech Inc.)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-04-14] (Malwarebytes Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20288 2014-09-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38048 2014-09-04] (NVIDIA Corporation)
R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13832 2010-04-16] ()
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-14 19:29 - 2015-04-14 19:30 - 00031301 _____ () C:\Users\Dave\Downloads\FRST.txt
2015-04-14 19:29 - 2015-04-14 19:29 - 00000000 ____D () C:\FRST
2015-04-14 19:28 - 2015-04-14 19:28 - 02096640 _____ (Farbar) C:\Users\Dave\Downloads\FRST64.exe
2015-04-14 19:23 - 2015-04-14 19:23 - 00000552 _____ () C:\Windows\PFRO.log
2015-04-14 19:23 - 2015-04-14 19:23 - 00000000 ____D () C:\KVRT_Data
2015-04-14 19:20 - 2015-04-14 19:22 - 115264856 _____ (Kaspersky Lab ZAO) C:\Users\Dave\Downloads\KVRT.exe
2015-04-14 19:13 - 2015-04-14 19:13 - 00036547 _____ () C:\ComboFix.txt
2015-04-14 19:06 - 2011-06-26 10:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-04-14 19:06 - 2010-11-07 21:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-04-14 19:06 - 2009-04-20 08:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-04-14 19:06 - 2000-08-31 04:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-04-14 19:06 - 2000-08-31 04:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-04-14 19:06 - 2000-08-31 04:00 - 00098816 _____ () C:\Windows\sed.exe
2015-04-14 19:06 - 2000-08-31 04:00 - 00080412 _____ () C:\Windows\grep.exe
2015-04-14 19:06 - 2000-08-31 04:00 - 00068096 _____ () C:\Windows\zip.exe
2015-04-14 19:05 - 2015-04-14 19:13 - 00000000 ____D () C:\Qoobox
2015-04-14 19:05 - 2015-04-14 19:11 - 00000000 ____D () C:\Windows\erdnt
2015-04-14 19:03 - 2015-04-14 19:03 - 00000000 ____D () C:\Users\Dave\Desktop\bootkit_remover
2015-04-14 19:02 - 2015-04-14 19:02 - 05617275 ____R (Swearware) C:\Users\Dave\Desktop\ComboFix.exe
2015-04-14 19:02 - 2015-04-14 19:02 - 05617275 _____ (Swearware) C:\Users\Dave\Downloads\ComboFix.exe
2015-04-14 18:59 - 2015-04-14 18:58 - 00044607 _____ () C:\Users\Dave\Desktop\bootkit_remover.zip
2015-04-14 18:58 - 2015-04-14 18:58 - 00044607 _____ () C:\Users\Dave\Downloads\bootkit_remover.zip
2015-04-14 18:10 - 2015-04-14 18:10 - 02212576 _____ () C:\Users\Dave\Downloads\VISTAS_2.dwg
2015-04-14 07:06 - 2015-04-14 07:06 - 05453878 _____ () C:\Users\Dave\Downloads\PRO_CON_20150413-v3.dwg
2015-04-14 07:05 - 2015-04-14 07:06 - 13711694 _____ () C:\Users\Dave\Downloads\wetransfer-47136d.zip
2015-04-13 18:26 - 2015-04-13 18:26 - 05286878 _____ () C:\Users\Dave\Downloads\PRO_CON_20150413-v2.dwg
2015-04-13 06:37 - 2015-04-13 06:37 - 02830825 _____ () C:\Users\Dave\Downloads\PRO_WD_201504011 Folder_v2.zip
2015-04-12 21:15 - 2015-04-12 21:15 - 00016339 _____ () C:\Users\Dave\Downloads\12-monkeys-first-season_english-1064043.zip
2015-04-12 19:50 - 2015-04-12 19:50 - 07036736 _____ () C:\Users\Dave\Downloads\PRO_CON_20150411_v5.dwg
2015-04-12 19:23 - 2015-04-12 19:23 - 01608519 _____ () C:\Users\Dave\Downloads\PRO_WD_201504011 Folder.zip
2015-04-10 17:11 - 2015-04-10 17:12 - 36862649 _____ () C:\Users\Dave\Downloads\PRO_WD_201504010-v1.zip
2015-04-10 17:08 - 2015-04-10 17:08 - 04806378 _____ () C:\Users\Dave\Downloads\CPR_Edificado_Volumentria_stp.skp
2015-04-10 09:18 - 2015-04-10 09:20 - 71993588 _____ () C:\Users\Dave\Downloads\wetransfer-8d7b8c.zip
2015-04-09 18:17 - 2015-04-09 18:40 - 00845748 _____ () C:\Users\Dave\Downloads\FATIAS_1 (2).dwg
2015-04-09 18:17 - 2015-04-09 18:17 - 00795488 _____ () C:\Users\Dave\Downloads\FATIAS_1 (2).bak
2015-04-07 18:39 - 2015-04-07 18:39 - 08034264 _____ () C:\Users\Dave\Downloads\PRO_WD_20150404_T.dwg
2015-04-05 16:18 - 2015-04-05 16:19 - 36171889 _____ () C:\Users\Dave\Downloads\PRO_WD_20150405.zip
2015-04-05 03:00 - 2015-04-05 03:00 - 00000000 ___SD () C:\Windows\SysWOW64\GWX
2015-04-05 03:00 - 2015-04-05 03:00 - 00000000 ___SD () C:\Windows\system32\GWX
2015-04-04 21:20 - 2015-04-04 21:20 - 05251456 _____ () C:\Users\Dave\Downloads\PRO_WD_20150404.dwg
2015-04-04 21:20 - 2015-04-04 21:20 - 05251456 _____ () C:\Users\Dave\Downloads\PRO_WD_20150404 (1).dwg
2015-04-04 21:11 - 2015-04-04 21:11 - 26546572 _____ () C:\Users\Dave\Downloads\Base_tatas_TRAB_04042015 - Standard_2.zip
2015-04-04 06:54 - 2015-04-04 06:55 - 39375217 _____ () C:\Users\Dave\Downloads\PRO_WD_20150403.zip
2015-04-03 22:43 - 2015-04-03 22:43 - 00000000 ____D () C:\Users\Dave\Downloads\pavingstone1_8215
2015-04-03 22:42 - 2015-04-03 22:43 - 07529415 _____ () C:\Users\Dave\Downloads\pavingstone1_8215.zip
2015-04-03 21:53 - 2015-04-03 21:53 - 01402034 _____ () C:\Users\Dave\Downloads\s8.skp
2015-04-03 21:51 - 2015-04-03 21:51 - 01402036 _____ () C:\Users\Dave\Downloads\s13.skp
2015-04-03 21:07 - 2015-04-03 21:07 - 02064134 _____ () C:\Users\Dave\Downloads\singapur.skp
2015-04-03 21:05 - 2015-04-03 21:06 - 01971586 _____ () C:\Users\Dave\Downloads\Component_22.skp
2015-04-03 21:05 - 2015-04-03 21:06 - 01208270 _____ () C:\Users\Dave\Downloads\# Container 40.skp
2015-04-03 21:05 - 2015-04-03 21:06 - 00956839 _____ () C:\Users\Dave\Downloads\# CONTAINER 20.skp
2015-04-03 12:43 - 2015-04-03 14:09 - 00181497 _____ () C:\Users\Dave\Downloads\cortes gerais_lena.dwg
2015-04-03 12:43 - 2015-04-03 12:43 - 00195520 _____ () C:\Users\Dave\Downloads\crt5.dwg
2015-04-03 12:43 - 2015-04-03 12:43 - 00098454 _____ () C:\Users\Dave\Downloads\cortes gerais_lena.bak
2015-03-31 23:40 - 2015-03-31 23:42 - 129759744 _____ () C:\Users\Dave\Downloads\PRO_R_29150327e_final.ppt
2015-03-31 23:36 - 2015-03-31 23:36 - 00000000 ____D () C:\Users\Dave\Downloads\CONCEITO_imagensREF
2015-03-31 23:35 - 2015-03-31 23:35 - 00000000 ____D () C:\Users\Dave\Downloads\DOC_20mar2015
2015-03-31 23:26 - 2015-04-14 18:54 - 00000556 _____ () C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-4239578433-150447082-3389053847-1000.job
2015-03-31 23:26 - 2015-04-12 23:10 - 00003576 _____ () C:\Windows\System32\Tasks\G2MUpdateTask-S-1-5-21-4239578433-150447082-3389053847-1000
2015-03-31 23:26 - 2015-03-31 23:26 - 01601250 _____ () C:\Users\Dave\Desktop\AttendeeViewerImage000.bmp
2015-03-31 23:26 - 2015-03-31 23:26 - 00002548 _____ () C:\Users\Dave\Desktop\GoToMeeting Quick Connect.lnk
2015-03-31 23:25 - 2015-03-31 23:26 - 00000000 ____D () C:\Users\Dave\AppData\Local\Citrix
2015-03-31 20:06 - 2015-03-31 20:08 - 26912271 _____ () C:\Users\Dave\Downloads\CONCEITO_imagensREF.zip
2015-03-31 19:55 - 2015-03-31 20:32 - 501125787 _____ () C:\Users\Dave\Downloads\FOTOS.zip
2015-03-31 19:55 - 2015-03-31 20:02 - 121280489 _____ () C:\Users\Dave\Downloads\VIDEO.zip
2015-03-31 19:55 - 2015-03-31 19:55 - 00007831 _____ () C:\Users\Dave\Downloads\DOC_20mar2015.zip
2015-03-31 19:54 - 2015-03-31 20:27 - 423246974 _____ () C:\Users\Dave\Downloads\visita_21mar2015.zip
2015-03-27 16:56 - 2015-03-27 16:56 - 00031710 _____ () C:\Users\Dave\Downloads\the-theory-of-everything-2014_english-1059743.zip
2015-03-27 16:36 - 2015-03-27 16:37 - 00020803 _____ () C:\Users\Dave\Downloads\song-of-the-sea_english-1081171.zip
2015-03-27 08:20 - 2015-03-27 08:22 - 113621504 _____ () C:\Users\Dave\Downloads\PRO_R_29150327e.ppt
2015-03-24 19:26 - 2015-03-24 19:26 - 00055582 _____ () C:\Users\Dave\Downloads\interstellar_english-1080247.zip
2015-03-20 00:26 - 2015-03-20 00:26 - 00023071 _____ () C:\Users\Dave\Downloads\reign-of-fire_english-94668.zip
2015-03-15 21:31 - 2015-03-15 21:31 - 00066177 _____ () C:\Users\Dave\Downloads\horrible-bosses-2_english-1062721.zip
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-14 19:30 - 2013-08-12 19:47 - 00000000 ____D () C:\Users\Dave\AppData\Roaming\uTorrent
2015-04-14 19:29 - 2009-07-14 08:45 - 00019968 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-14 19:29 - 2009-07-14 08:45 - 00019968 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-14 19:27 - 2015-03-07 20:29 - 01387115 _____ () C:\Windows\WindowsUpdate.log
2015-04-14 19:25 - 2015-02-25 22:34 - 00000000 ___HD () C:\Users\Dave\AppData\Roaming\sduisg
2015-04-14 19:25 - 2014-03-05 18:57 - 00000000 ___RD () C:\Users\Dave\Dropbox
2015-04-14 19:25 - 2014-03-05 18:55 - 00000000 ____D () C:\Users\Dave\AppData\Roaming\Dropbox
2015-04-14 19:24 - 2015-03-07 20:27 - 00003370 _____ () C:\Windows\setupact.log
2015-04-14 19:24 - 2015-02-28 19:27 - 00000000 ____D () C:\ProgramData\MCShield
2015-04-14 19:24 - 2013-08-23 16:28 - 00000000 ____D () C:\Users\Dave\AppData\Roaming\ViberPC
2015-04-14 19:24 - 2013-08-23 16:27 - 00000000 ____D () C:\Users\Dave\AppData\Local\Viber
2015-04-14 19:24 - 2013-08-12 19:12 - 00001004 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-14 19:24 - 2009-07-14 09:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-14 19:23 - 2013-08-12 19:36 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-04-14 19:16 - 2014-07-06 23:36 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-14 19:13 - 2009-07-14 07:20 - 00000000 __RHD () C:\Users\Default
2015-04-14 19:11 - 2009-07-14 06:34 - 00000215 _____ () C:\Windows\system.ini
2015-04-14 18:55 - 2013-08-13 21:19 - 00001014 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4239578433-150447082-3389053847-1000UA.job
2015-04-14 18:55 - 2013-08-13 21:19 - 00000962 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4239578433-150447082-3389053847-1000Core.job
2015-04-14 18:26 - 2009-07-14 09:13 - 00782470 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-14 18:22 - 2013-08-15 14:58 - 00000000 ____D () C:\ProgramData\MFAData
2015-04-14 18:17 - 2013-08-21 13:43 - 00000000 ____D () C:\Users\Dave\AppData\Roaming\Winamp
2015-04-14 18:13 - 2014-08-10 20:11 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-14 18:09 - 2013-08-12 19:12 - 00001008 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-04-13 20:06 - 2013-08-12 19:54 - 00000000 ____D () C:\Users\Dave\AppData\Roaming\vlc
2015-04-13 04:02 - 2014-03-05 18:57 - 00001012 _____ () C:\Users\Dave\Desktop\Dropbox.lnk
2015-04-13 04:02 - 2014-03-05 18:56 - 00000000 ____D () C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-04-10 20:29 - 2013-08-12 23:29 - 00000000 ____D () C:\Users\Dave\AppData\Local\cache
2015-04-09 08:02 - 2013-08-13 21:19 - 00000000 ____D () C:\Users\Dave\AppData\Roaming\Mozilla
2015-04-04 20:20 - 2013-09-28 23:12 - 00000000 ____D () C:\Users\Dave\AppData\Roaming\Skype
2015-04-03 15:51 - 2013-09-29 00:47 - 00000132 _____ () C:\Users\Dave\AppData\Roaming\Adobe PNG Format CS6 Prefs
2015-04-03 14:07 - 2014-10-30 08:25 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-03-31 04:41 - 2009-07-14 07:20 - 00000000 ____D () C:\Windows\rescache
2015-03-27 23:56 - 2013-09-19 01:35 - 00000000 ____D () C:\ProgramData\P4G
2015-03-27 23:56 - 2013-08-23 13:16 - 00000000 ____D () C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2015-03-27 23:56 - 2013-08-15 15:35 - 00000000 ____D () C:\Users\Dave\AppData\Local\Mozilla
2015-03-27 23:56 - 2013-08-12 23:18 - 00000000 ____D () C:\ExpressGateUtil
2015-03-27 23:56 - 2013-08-12 19:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-03-27 23:56 - 2009-07-14 07:20 - 00000000 ____D () C:\Windows\registration
2015-03-27 23:56 - 2009-07-14 07:20 - 00000000 ____D () C:\Windows\AppCompat
2015-03-27 12:00 - 2013-08-12 18:42 - 00000000 ____D () C:\Users\Dave
2015-03-26 00:17 - 2014-08-10 20:16 - 00000000 ____D () C:\Users\Dave\AppData\Local\Adobe
==================== Files in the root of some directories =======
2013-10-03 23:20 - 2013-10-03 23:21 - 0102357 _____ () C:\Program Files\unins000.dat
2013-10-03 23:20 - 2013-10-03 23:20 - 0736929 _____ () C:\Program Files\unins000.exe
2013-09-27 23:52 - 2013-10-13 11:05 - 0000132 _____ () C:\Users\Dave\AppData\Roaming\Adobe OpenEXR Format CS6 Prefs
2013-09-29 00:47 - 2015-04-03 15:51 - 0000132 _____ () C:\Users\Dave\AppData\Roaming\Adobe PNG Format CS6 Prefs
2013-09-10 11:57 - 2013-09-10 11:57 - 0000037 ___SH () C:\Users\Dave\AppData\Local\70149b02515b3bb20dd492.47983420
2013-10-06 22:33 - 2013-10-06 22:33 - 0007613 _____ () C:\Users\Dave\AppData\Local\Resmon.ResmonCfg
2014-12-03 18:18 - 2014-12-03 18:18 - 0000057 _____ () C:\ProgramData\Ament.ini
2013-08-12 20:32 - 2013-08-12 20:32 - 0000153 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
Some content of TEMP:
====================
C:\Users\Dave\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpqipyte.dll
C:\Users\Dave\AppData\Local\Temp\{B930B6AF-9844-47CA-B2B4-54D5CB95DCB2}.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-04-14 00:34
==================== End Of Log ============================
I found the computer having a strange behaviour, the cpu is working hard even when I am not running any software that causes it. Also, sometimes ccleaner or mawarebites wont open if I dont boot in safe mode.
Here are my logs:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-04-2015
Ran by Dave (administrator) on LEGIAO on 14-04-2015 19:29:40
Running from C:\Users\Dave\Downloads
Loaded Profiles: Dave (Available profiles: Dave)
Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Autodesk, Inc.) C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(ASUS) C:\Program Files\ASUS\P4G\BatteryLife.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\USBChargerPlus\USBChargerPlus.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
() C:\Program Files\Autodesk\3ds Max 2014\NVIDIA\Satellite\raysat_3dsmax2014_64server.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgemca.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe
() C:\ExpressGateUtil\VAWinService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Kaspersky Lab ZAO) C:\Users\Dave\AppData\Local\Temp\{B930B6AF-9844-47CA-B2B4-54D5CB95DCB2}.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Logitech Inc.) C:\Program Files\Logitech Gaming Software\LCore.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe
(Sentelic Corporation) C:\Program Files\FSP\FspUip.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe
(BitTorrent Inc.) C:\Users\Dave\AppData\Roaming\uTorrent\uTorrent.exe
() C:\Users\Dave\AppData\Local\Viber\Viber.exe
(Dropbox, Inc.) C:\Users\Dave\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
() C:\ExpressGateUtil\VAWinAgent.exe
(Windows (R) Win 7 DDK provider) C:\Program Files\Fresco Logic\Fresco Logic USB3.0 Host Controller\amd64_host\FLxHCIm.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgui.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\acrotray.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12446824 2012-01-31] (Realtek Semiconductor)
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM\...\Run: [Launch LCore] => C:\Program Files\Logitech Gaming Software\LCore.exe [7477016 2013-04-25] (Logitech Inc.)
HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3091224 2013-08-01] (Logitech, Inc.)
HKLM\...\Run: [Autodesk Sync] => C:\Program Files\Autodesk\Autodesk Sync\AdSync.exe [418280 2012-07-26] (Autodesk, Inc.)
HKLM\...\Run: [fspuip] => C:\Program Files\FSP\fspuip.exe [4285952 2011-06-19] (Sentelic Corporation)
HKLM\...\Run: [THXCfg64] => C:\Windows\system32\RunDLL32.exe C:\Windows\system32\THXCfg64.dll,RunDLLEntry THXCfg64
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2461504 2014-09-17] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM-x32\...\Run: [VAWinAgent] => C:\ExpressGateUtil\VAWinAgent.exe [45448 2011-04-08] ()
HKLM-x32\...\Run: [FLxHCIm64] => C:\Program Files\Fresco Logic\Fresco Logic USB3.0 Host Controller\amd64_host\FLxHCIm.exe [48128 2012-07-19] (Windows (R) Win 7 DDK provider)
HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [2321072 2012-02-02] (ASUSTeK Computer Inc.)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [318080 2011-12-22] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [174720 2011-10-24] (ASUS)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [THX TruStudio NB Settings] => C:\Program Files (x86)\Creative\THX TruStudio\THXNBSet\THXAudNB.exe [909312 2011-03-16] (Creative Technology Ltd)
HKLM-x32\...\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2013\avgui.exe [4411952 2014-11-04] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Acrotray.exe [3478392 2013-09-05] (Adobe Systems Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\RunOnce: [{7F899E6A-EA93-47DC-88DA-5EE53B87FDDB}] => cmd.exe /C start /D "C:\Users\Dave\AppData\Local\Temp" /B {7F899E6A-EA93-47DC-88DA-5EE53B87FDDB}.cmd
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-4239578433-150447082-3389053847-1000\...\Run: [uTorrent] => C:\Users\Dave\AppData\Roaming\uTorrent\uTorrent.exe [1377872 2015-01-30] (BitTorrent Inc.)
HKU\S-1-5-21-4239578433-150447082-3389053847-1000\...\Run: [DAEMON Tools Lite] => C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe [3673696 2013-08-01] (Disc Soft Ltd)
HKU\S-1-5-21-4239578433-150447082-3389053847-1000\...\Run: [Viber] => C:\Users\Dave\AppData\Local\Viber\Viber.exe [912904 2013-07-31] ()
HKU\S-1-5-21-4239578433-150447082-3389053847-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7416088 2015-02-19] (Piriform Ltd)
HKU\S-1-5-21-4239578433-150447082-3389053847-1000\...\Run: [MCShield Monitor] => C:\Program Files (x86)\MCShield\mcshieldrtm.exe [650816 2014-04-11] (MyCity)
HKU\S-1-5-21-4239578433-150447082-3389053847-1000\...\Policies\Explorer: []
Startup: C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Dave\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Logitech . Registo do produto.lnk
ShortcutTarget: Logitech . Registo do produto.lnk -> C:\Program Files (x86)\Common Files\LogiShrd\eReg\SetPoint\eReg.exe (Leader Technologies/Logitech)
Startup: C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Deskjet 1510 series.lnk
ShortcutTarget: Monitor Ink Alerts - HP Deskjet 1510 series.lnk -> C:\Program Files\HP\HP Deskjet 1510 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
Startup: C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Windows Explorer.lnk
ShortcutTarget: Windows Explorer.lnk -> C:\Users\Dave\AppData\Roaming\sduisg\diskmonitor.exe (Microsoft Corporation)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\Windows\system32\AcSignIcon.dll (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt64.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Dave\AppData\Roaming\Dropbox\bin\DropboxExt.25.dll (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\S-1-5-21-4239578433-150447082-3389053847-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-4239578433-150447082-3389053847-1000\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2013-10-17] (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2013-09-05] (Adobe Systems Incorporated)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2013-08-01] (Logitech, Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2013-09-13] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2013-11-02] (Microsoft Corporation)
BHO: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2013-09-05] (Adobe Systems Incorporated)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2013-10-17] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-09-18] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO-x32: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File
BHO-x32: Adobe Acrobat Create PDF Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2013-09-05] (Adobe Systems Incorporated)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2013-08-01] (Logitech, Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2013-09-13] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2013-11-02] (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-09-18] (Oracle Corporation)
BHO-x32: Adobe Acrobat Create PDF from Selection -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2013-09-05] (Adobe Systems Incorporated)
Toolbar: HKLM - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\x64\AcroIEFavClient.dll [2013-09-05] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Adobe Acrobat Create PDF Toolbar - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\WCIEActiveX\AcroIEFavClient.dll [2013-09-05] (Adobe Systems Incorporated)
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2014-07-14] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2014-07-14] (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Dave\AppData\Roaming\Mozilla\Firefox\Profiles\0rp4oki1.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll [2015-02-06] ()
FF Plugin: @garmin.com/GpsControl -> C:\Program Files\Garmin GPS Plugin\npGarmin.dll [2014-03-31] (GARMIN Corp.)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2012-09-20] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll [2015-02-06] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2013-09-09] ()
FF Plugin-x32: @garmin.com/GpsControl -> C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll [2014-03-31] (GARMIN Corp.)
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2013-10-07] (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.40.2 -> C:\Windows\SysWOW64\npDeployJava1.dll [2013-09-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.40.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2013-09-18] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2013-10-17] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @nullsoft.com/winampDetector;version=1 -> C:\Program Files (x86)\Winamp Detect\npwachk.dll [2013-07-24] (Nullsoft, Inc.)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2014-11-13] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2014-11-13] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-05] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2014-07-23] (VideoLAN)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Air\nppdf32.dll [2013-09-26] (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2012-09-20] (Adobe Systems)
FF Plugin HKU\S-1-5-21-4239578433-150447082-3389053847-1000: @citrixonline.com/appdetectorplugin -> C:\Users\Dave\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2015-03-31] (Citrix Online)
FF Plugin HKU\S-1-5-21-4239578433-150447082-3389053847-1000: @talk.google.com/GoogleTalkPlugin -> C:\Users\Dave\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-03-26] (Google)
FF Plugin HKU\S-1-5-21-4239578433-150447082-3389053847-1000: @talk.google.com/O1DPlugin -> C:\Users\Dave\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-03-26] (Google)
FF Plugin HKU\S-1-5-21-4239578433-150447082-3389053847-1000: @tools.google.com/Google Update;version=3 -> C:\Users\Dave\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-08] (Google Inc.)
FF Plugin HKU\S-1-5-21-4239578433-150447082-3389053847-1000: @tools.google.com/Google Update;version=9 -> C:\Users\Dave\AppData\Local\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-08] (Google Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2013-10-17] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Dave\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-03-26] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Dave\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-03-26] (Google)
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2014-10-30]
FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: Logitech SetPoint - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2013-08-12]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCFirefoxExtn [2013-11-20]
Chrome:
=======
CHR Profile: C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2014-10-12]
CHR Extension: (Google Docs) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-10-12]
CHR Extension: (Google Drive) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-10-12]
CHR Extension: (YouTube) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-10-12]
CHR Extension: (Google Search) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-10-12]
CHR Extension: (Adobe Acrobat - Create PDF) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2013-12-02]
CHR Extension: (Google Sheets) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-10-12]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-03-12]
CHR Extension: (Skype Click to Call) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-09-07]
CHR Extension: (Google Wallet) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-09-07]
CHR Extension: (Gmail) - C:\Users\Dave\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-10-12]
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - C:\Program Files (x86)\Adobe\Acrobat 11.0\Acrobat\Browser\WCChromeExtn\WCChromeExtn.crx [2013-09-05]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
CHR HKLM-x32\...\Chrome\Extension: [oejkcgajlodefenbbjdnaiahmbnnoole] - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\chrome-newtab-search.crx [Not Found]
Opera:
=======
StartMenuInternet: (HKU\S-1-5-21-4239578433-150447082-3389053847-1000) OperaMail - "C:\Users\Dave\AppData\Local\Opera Mail\OperaMail.exe"
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [19232 2012-01-31] (Autodesk, Inc.)
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [4942384 2014-10-17] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [283136 2013-11-20] (AVG Technologies CZ, s.r.o.)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
S3 Creative ALchemy AL6 Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [79360 2013-08-15] (Creative Labs) [File not signed]
S3 Creative Audio Engine Licensing Service; C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [79360 2013-08-15] (Creative Labs) [File not signed]
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [654848 2013-09-15] (Macrovision Europe Ltd.) [File not signed]
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1149760 2014-09-17] (NVIDIA Corporation)
R2 mi-raysat_3dsmax2014_64; C:\Program Files\Autodesk\3ds Max 2014\NVIDIA\Satellite\raysat_3dsmax2014_64server.exe [86016 2011-09-15] () [File not signed]
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1796928 2014-09-17] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19440960 2014-09-17] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-08-22] ()
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 VideAceWindowsService; C:\ExpressGateUtil\VAWinService.exe [91464 2011-03-25] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R0 4EEDD889; C:\Windows\System32\drivers\4EEDD889.sys [457824 2015-04-14] (Kaspersky Lab ZAO)
R3 AiCharger; C:\Windows\SysWOW64\DRIVERS\AiCharger.sys [17152 2012-01-30] (ASUSTek Computer Inc.)
R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [246072 2013-11-25] (AVG Technologies CZ, s.r.o.)
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [71480 2013-07-20] (AVG Technologies CZ, s.r.o.)
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [209720 2014-11-04] (AVG Technologies CZ, s.r.o.)
R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [311608 2013-07-20] (AVG Technologies CZ, s.r.o.)
R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [116536 2013-07-01] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [45880 2013-10-23] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [240952 2014-10-17] (AVG Technologies CZ, s.r.o.)
S3 cpuz135; C:\Program Files (x86)\CPUID\PC Wizard 2012\pcwiz_x64.sys [24368 2012-08-11] (CPUID)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283064 2013-08-12] (Disc Soft Ltd)
R3 FLxHCIh; C:\Windows\System32\DRIVERS\FLxHCIh.sys [76584 2012-07-19] (Fresco Logic)
R3 fspad_win764; C:\Windows\System32\DRIVERS\fspad_win764.sys [53760 2011-06-19] (Windows (R) Win 7 DDK provider)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-08-15] (GFI Software)
S3 ggsomc; C:\Windows\System32\DRIVERS\ggsomc.sys [30424 2014-12-25] (Sony Mobile Communications)
R3 LGSHidFilt; C:\Windows\System32\DRIVERS\LGSHidFilt.Sys [66800 2013-01-17] (Logitech Inc.)
R3 LGSUsbFilt; C:\Windows\System32\DRIVERS\LGSUsbFilt.Sys [44272 2013-01-17] (Logitech Inc.)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-04-14] (Malwarebytes Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20288 2014-09-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38048 2014-09-04] (NVIDIA Corporation)
R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13832 2010-04-16] ()
S3 catchme; \??\C:\ComboFix\catchme.sys [X]
S3 ewusbnet; system32\DRIVERS\ewusbnet.sys [X]
S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X]
S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [X]
S3 tsusbhub; system32\drivers\tsusbhub.sys [X]
S3 VGPU; System32\drivers\rdvgkmd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-14 19:29 - 2015-04-14 19:30 - 00031301 _____ () C:\Users\Dave\Downloads\FRST.txt
2015-04-14 19:29 - 2015-04-14 19:29 - 00000000 ____D () C:\FRST
2015-04-14 19:28 - 2015-04-14 19:28 - 02096640 _____ (Farbar) C:\Users\Dave\Downloads\FRST64.exe
2015-04-14 19:23 - 2015-04-14 19:23 - 00000552 _____ () C:\Windows\PFRO.log
2015-04-14 19:23 - 2015-04-14 19:23 - 00000000 ____D () C:\KVRT_Data
2015-04-14 19:20 - 2015-04-14 19:22 - 115264856 _____ (Kaspersky Lab ZAO) C:\Users\Dave\Downloads\KVRT.exe
2015-04-14 19:13 - 2015-04-14 19:13 - 00036547 _____ () C:\ComboFix.txt
2015-04-14 19:06 - 2011-06-26 10:45 - 00256000 _____ () C:\Windows\PEV.exe
2015-04-14 19:06 - 2010-11-07 21:20 - 00208896 _____ () C:\Windows\MBR.exe
2015-04-14 19:06 - 2009-04-20 08:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2015-04-14 19:06 - 2000-08-31 04:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2015-04-14 19:06 - 2000-08-31 04:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2015-04-14 19:06 - 2000-08-31 04:00 - 00098816 _____ () C:\Windows\sed.exe
2015-04-14 19:06 - 2000-08-31 04:00 - 00080412 _____ () C:\Windows\grep.exe
2015-04-14 19:06 - 2000-08-31 04:00 - 00068096 _____ () C:\Windows\zip.exe
2015-04-14 19:05 - 2015-04-14 19:13 - 00000000 ____D () C:\Qoobox
2015-04-14 19:05 - 2015-04-14 19:11 - 00000000 ____D () C:\Windows\erdnt
2015-04-14 19:03 - 2015-04-14 19:03 - 00000000 ____D () C:\Users\Dave\Desktop\bootkit_remover
2015-04-14 19:02 - 2015-04-14 19:02 - 05617275 ____R (Swearware) C:\Users\Dave\Desktop\ComboFix.exe
2015-04-14 19:02 - 2015-04-14 19:02 - 05617275 _____ (Swearware) C:\Users\Dave\Downloads\ComboFix.exe
2015-04-14 18:59 - 2015-04-14 18:58 - 00044607 _____ () C:\Users\Dave\Desktop\bootkit_remover.zip
2015-04-14 18:58 - 2015-04-14 18:58 - 00044607 _____ () C:\Users\Dave\Downloads\bootkit_remover.zip
2015-04-14 18:10 - 2015-04-14 18:10 - 02212576 _____ () C:\Users\Dave\Downloads\VISTAS_2.dwg
2015-04-14 07:06 - 2015-04-14 07:06 - 05453878 _____ () C:\Users\Dave\Downloads\PRO_CON_20150413-v3.dwg
2015-04-14 07:05 - 2015-04-14 07:06 - 13711694 _____ () C:\Users\Dave\Downloads\wetransfer-47136d.zip
2015-04-13 18:26 - 2015-04-13 18:26 - 05286878 _____ () C:\Users\Dave\Downloads\PRO_CON_20150413-v2.dwg
2015-04-13 06:37 - 2015-04-13 06:37 - 02830825 _____ () C:\Users\Dave\Downloads\PRO_WD_201504011 Folder_v2.zip
2015-04-12 21:15 - 2015-04-12 21:15 - 00016339 _____ () C:\Users\Dave\Downloads\12-monkeys-first-season_english-1064043.zip
2015-04-12 19:50 - 2015-04-12 19:50 - 07036736 _____ () C:\Users\Dave\Downloads\PRO_CON_20150411_v5.dwg
2015-04-12 19:23 - 2015-04-12 19:23 - 01608519 _____ () C:\Users\Dave\Downloads\PRO_WD_201504011 Folder.zip
2015-04-10 17:11 - 2015-04-10 17:12 - 36862649 _____ () C:\Users\Dave\Downloads\PRO_WD_201504010-v1.zip
2015-04-10 17:08 - 2015-04-10 17:08 - 04806378 _____ () C:\Users\Dave\Downloads\CPR_Edificado_Volumentria_stp.skp
2015-04-10 09:18 - 2015-04-10 09:20 - 71993588 _____ () C:\Users\Dave\Downloads\wetransfer-8d7b8c.zip
2015-04-09 18:17 - 2015-04-09 18:40 - 00845748 _____ () C:\Users\Dave\Downloads\FATIAS_1 (2).dwg
2015-04-09 18:17 - 2015-04-09 18:17 - 00795488 _____ () C:\Users\Dave\Downloads\FATIAS_1 (2).bak
2015-04-07 18:39 - 2015-04-07 18:39 - 08034264 _____ () C:\Users\Dave\Downloads\PRO_WD_20150404_T.dwg
2015-04-05 16:18 - 2015-04-05 16:19 - 36171889 _____ () C:\Users\Dave\Downloads\PRO_WD_20150405.zip
2015-04-05 03:00 - 2015-04-05 03:00 - 00000000 ___SD () C:\Windows\SysWOW64\GWX
2015-04-05 03:00 - 2015-04-05 03:00 - 00000000 ___SD () C:\Windows\system32\GWX
2015-04-04 21:20 - 2015-04-04 21:20 - 05251456 _____ () C:\Users\Dave\Downloads\PRO_WD_20150404.dwg
2015-04-04 21:20 - 2015-04-04 21:20 - 05251456 _____ () C:\Users\Dave\Downloads\PRO_WD_20150404 (1).dwg
2015-04-04 21:11 - 2015-04-04 21:11 - 26546572 _____ () C:\Users\Dave\Downloads\Base_tatas_TRAB_04042015 - Standard_2.zip
2015-04-04 06:54 - 2015-04-04 06:55 - 39375217 _____ () C:\Users\Dave\Downloads\PRO_WD_20150403.zip
2015-04-03 22:43 - 2015-04-03 22:43 - 00000000 ____D () C:\Users\Dave\Downloads\pavingstone1_8215
2015-04-03 22:42 - 2015-04-03 22:43 - 07529415 _____ () C:\Users\Dave\Downloads\pavingstone1_8215.zip
2015-04-03 21:53 - 2015-04-03 21:53 - 01402034 _____ () C:\Users\Dave\Downloads\s8.skp
2015-04-03 21:51 - 2015-04-03 21:51 - 01402036 _____ () C:\Users\Dave\Downloads\s13.skp
2015-04-03 21:07 - 2015-04-03 21:07 - 02064134 _____ () C:\Users\Dave\Downloads\singapur.skp
2015-04-03 21:05 - 2015-04-03 21:06 - 01971586 _____ () C:\Users\Dave\Downloads\Component_22.skp
2015-04-03 21:05 - 2015-04-03 21:06 - 01208270 _____ () C:\Users\Dave\Downloads\# Container 40.skp
2015-04-03 21:05 - 2015-04-03 21:06 - 00956839 _____ () C:\Users\Dave\Downloads\# CONTAINER 20.skp
2015-04-03 12:43 - 2015-04-03 14:09 - 00181497 _____ () C:\Users\Dave\Downloads\cortes gerais_lena.dwg
2015-04-03 12:43 - 2015-04-03 12:43 - 00195520 _____ () C:\Users\Dave\Downloads\crt5.dwg
2015-04-03 12:43 - 2015-04-03 12:43 - 00098454 _____ () C:\Users\Dave\Downloads\cortes gerais_lena.bak
2015-03-31 23:40 - 2015-03-31 23:42 - 129759744 _____ () C:\Users\Dave\Downloads\PRO_R_29150327e_final.ppt
2015-03-31 23:36 - 2015-03-31 23:36 - 00000000 ____D () C:\Users\Dave\Downloads\CONCEITO_imagensREF
2015-03-31 23:35 - 2015-03-31 23:35 - 00000000 ____D () C:\Users\Dave\Downloads\DOC_20mar2015
2015-03-31 23:26 - 2015-04-14 18:54 - 00000556 _____ () C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-4239578433-150447082-3389053847-1000.job
2015-03-31 23:26 - 2015-04-12 23:10 - 00003576 _____ () C:\Windows\System32\Tasks\G2MUpdateTask-S-1-5-21-4239578433-150447082-3389053847-1000
2015-03-31 23:26 - 2015-03-31 23:26 - 01601250 _____ () C:\Users\Dave\Desktop\AttendeeViewerImage000.bmp
2015-03-31 23:26 - 2015-03-31 23:26 - 00002548 _____ () C:\Users\Dave\Desktop\GoToMeeting Quick Connect.lnk
2015-03-31 23:25 - 2015-03-31 23:26 - 00000000 ____D () C:\Users\Dave\AppData\Local\Citrix
2015-03-31 20:06 - 2015-03-31 20:08 - 26912271 _____ () C:\Users\Dave\Downloads\CONCEITO_imagensREF.zip
2015-03-31 19:55 - 2015-03-31 20:32 - 501125787 _____ () C:\Users\Dave\Downloads\FOTOS.zip
2015-03-31 19:55 - 2015-03-31 20:02 - 121280489 _____ () C:\Users\Dave\Downloads\VIDEO.zip
2015-03-31 19:55 - 2015-03-31 19:55 - 00007831 _____ () C:\Users\Dave\Downloads\DOC_20mar2015.zip
2015-03-31 19:54 - 2015-03-31 20:27 - 423246974 _____ () C:\Users\Dave\Downloads\visita_21mar2015.zip
2015-03-27 16:56 - 2015-03-27 16:56 - 00031710 _____ () C:\Users\Dave\Downloads\the-theory-of-everything-2014_english-1059743.zip
2015-03-27 16:36 - 2015-03-27 16:37 - 00020803 _____ () C:\Users\Dave\Downloads\song-of-the-sea_english-1081171.zip
2015-03-27 08:20 - 2015-03-27 08:22 - 113621504 _____ () C:\Users\Dave\Downloads\PRO_R_29150327e.ppt
2015-03-24 19:26 - 2015-03-24 19:26 - 00055582 _____ () C:\Users\Dave\Downloads\interstellar_english-1080247.zip
2015-03-20 00:26 - 2015-03-20 00:26 - 00023071 _____ () C:\Users\Dave\Downloads\reign-of-fire_english-94668.zip
2015-03-15 21:31 - 2015-03-15 21:31 - 00066177 _____ () C:\Users\Dave\Downloads\horrible-bosses-2_english-1062721.zip
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-04-14 19:30 - 2013-08-12 19:47 - 00000000 ____D () C:\Users\Dave\AppData\Roaming\uTorrent
2015-04-14 19:29 - 2009-07-14 08:45 - 00019968 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-04-14 19:29 - 2009-07-14 08:45 - 00019968 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-04-14 19:27 - 2015-03-07 20:29 - 01387115 _____ () C:\Windows\WindowsUpdate.log
2015-04-14 19:25 - 2015-02-25 22:34 - 00000000 ___HD () C:\Users\Dave\AppData\Roaming\sduisg
2015-04-14 19:25 - 2014-03-05 18:57 - 00000000 ___RD () C:\Users\Dave\Dropbox
2015-04-14 19:25 - 2014-03-05 18:55 - 00000000 ____D () C:\Users\Dave\AppData\Roaming\Dropbox
2015-04-14 19:24 - 2015-03-07 20:27 - 00003370 _____ () C:\Windows\setupact.log
2015-04-14 19:24 - 2015-02-28 19:27 - 00000000 ____D () C:\ProgramData\MCShield
2015-04-14 19:24 - 2013-08-23 16:28 - 00000000 ____D () C:\Users\Dave\AppData\Roaming\ViberPC
2015-04-14 19:24 - 2013-08-23 16:27 - 00000000 ____D () C:\Users\Dave\AppData\Local\Viber
2015-04-14 19:24 - 2013-08-12 19:12 - 00001004 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-04-14 19:24 - 2009-07-14 09:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-04-14 19:23 - 2013-08-12 19:36 - 00000000 ____D () C:\ProgramData\NVIDIA
2015-04-14 19:16 - 2014-07-06 23:36 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-04-14 19:13 - 2009-07-14 07:20 - 00000000 __RHD () C:\Users\Default
2015-04-14 19:11 - 2009-07-14 06:34 - 00000215 _____ () C:\Windows\system.ini
2015-04-14 18:55 - 2013-08-13 21:19 - 00001014 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4239578433-150447082-3389053847-1000UA.job
2015-04-14 18:55 - 2013-08-13 21:19 - 00000962 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-4239578433-150447082-3389053847-1000Core.job
2015-04-14 18:26 - 2009-07-14 09:13 - 00782470 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-04-14 18:22 - 2013-08-15 14:58 - 00000000 ____D () C:\ProgramData\MFAData
2015-04-14 18:17 - 2013-08-21 13:43 - 00000000 ____D () C:\Users\Dave\AppData\Roaming\Winamp
2015-04-14 18:13 - 2014-08-10 20:11 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-04-14 18:09 - 2013-08-12 19:12 - 00001008 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-04-13 20:06 - 2013-08-12 19:54 - 00000000 ____D () C:\Users\Dave\AppData\Roaming\vlc
2015-04-13 04:02 - 2014-03-05 18:57 - 00001012 _____ () C:\Users\Dave\Desktop\Dropbox.lnk
2015-04-13 04:02 - 2014-03-05 18:56 - 00000000 ____D () C:\Users\Dave\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2015-04-10 20:29 - 2013-08-12 23:29 - 00000000 ____D () C:\Users\Dave\AppData\Local\cache
2015-04-09 08:02 - 2013-08-13 21:19 - 00000000 ____D () C:\Users\Dave\AppData\Roaming\Mozilla
2015-04-04 20:20 - 2013-09-28 23:12 - 00000000 ____D () C:\Users\Dave\AppData\Roaming\Skype
2015-04-03 15:51 - 2013-09-29 00:47 - 00000132 _____ () C:\Users\Dave\AppData\Roaming\Adobe PNG Format CS6 Prefs
2015-04-03 14:07 - 2014-10-30 08:25 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-03-31 04:41 - 2009-07-14 07:20 - 00000000 ____D () C:\Windows\rescache
2015-03-27 23:56 - 2013-09-19 01:35 - 00000000 ____D () C:\ProgramData\P4G
2015-03-27 23:56 - 2013-08-23 13:16 - 00000000 ____D () C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
2015-03-27 23:56 - 2013-08-15 15:35 - 00000000 ____D () C:\Users\Dave\AppData\Local\Mozilla
2015-03-27 23:56 - 2013-08-12 23:18 - 00000000 ____D () C:\ExpressGateUtil
2015-03-27 23:56 - 2013-08-12 19:13 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2015-03-27 23:56 - 2009-07-14 07:20 - 00000000 ____D () C:\Windows\registration
2015-03-27 23:56 - 2009-07-14 07:20 - 00000000 ____D () C:\Windows\AppCompat
2015-03-27 12:00 - 2013-08-12 18:42 - 00000000 ____D () C:\Users\Dave
2015-03-26 00:17 - 2014-08-10 20:16 - 00000000 ____D () C:\Users\Dave\AppData\Local\Adobe
==================== Files in the root of some directories =======
2013-10-03 23:20 - 2013-10-03 23:21 - 0102357 _____ () C:\Program Files\unins000.dat
2013-10-03 23:20 - 2013-10-03 23:20 - 0736929 _____ () C:\Program Files\unins000.exe
2013-09-27 23:52 - 2013-10-13 11:05 - 0000132 _____ () C:\Users\Dave\AppData\Roaming\Adobe OpenEXR Format CS6 Prefs
2013-09-29 00:47 - 2015-04-03 15:51 - 0000132 _____ () C:\Users\Dave\AppData\Roaming\Adobe PNG Format CS6 Prefs
2013-09-10 11:57 - 2013-09-10 11:57 - 0000037 ___SH () C:\Users\Dave\AppData\Local\70149b02515b3bb20dd492.47983420
2013-10-06 22:33 - 2013-10-06 22:33 - 0007613 _____ () C:\Users\Dave\AppData\Local\Resmon.ResmonCfg
2014-12-03 18:18 - 2014-12-03 18:18 - 0000057 _____ () C:\ProgramData\Ament.ini
2013-08-12 20:32 - 2013-08-12 20:32 - 0000153 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.32.bc
Some content of TEMP:
====================
C:\Users\Dave\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpqipyte.dll
C:\Users\Dave\AppData\Local\Temp\{B930B6AF-9844-47CA-B2B4-54D5CB95DCB2}.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-04-14 00:34
==================== End Of Log ============================